Monday, October 13, 2025

The Top 5 Pinterest...

As a blogger, using Pinterest can be an amazing way to drive traffic...

SEO Hacks to Skyrocket...

Search Engine Optimization, commonly known as SEO, is a crucial aspect of creating...

Google Lawsuits Update

Impact of AI on Search and Google Lawsuits We've been focused on the impact...

Reddit Mods Accuse AI...

Introduction to the Controversy The University of Zurich has been at the center of...
HomeWordpressMultiple WordPress Vulnerabilities...

Multiple WordPress Vulnerabilities Affect 20,000+ Travel Sites

Introduction to WP Travel Engine Vulnerabilities

The WP Travel Engine is a popular WordPress plugin used by travel agencies to enable users to plan itineraries, select from different packages, and book any kind of vacation. Recently, two critical vulnerabilities were identified in this plugin, which is installed on more than 20,000 websites. Both vulnerabilities enable unauthenticated attackers to obtain virtually complete control of a website and are rated 9.8 on the CVSS scale, very close to the highest possible score for critical flaws.

What is WP Travel Engine?

The WP Travel Engine is a travel booking plugin for WordPress that allows users to book vacations and travel packages. It is a popular choice among travel agencies due to its ease of use and flexibility. However, the recent discovery of vulnerabilities in the plugin has raised concerns about its security.

Improper Path Restriction (Path Traversal)

The first vulnerability comes from improper file path restriction in the plugin’s set_user_profile_image function. Because the plugin fails to validate file paths, unauthenticated attackers can rename or delete files anywhere on the server. Deleting a file such as wp-config.php disables the site’s configuration and can allow remote code execution. This flaw can enable an attacker to stage a remote code execution attack from the site.

- Advertisement -

Local File Inclusion via Mode Parameter

The second vulnerability comes from improper control of the mode parameter, which lets unauthenticated users include and run arbitrary .php files. This enables an attacker to run malicious code and access sensitive data. Like the first flaw, it has a CVSS score of 9.8 and is rated as critical because it allows unauthenticated code execution that can expose or damage site data.

Recommendation

Both vulnerabilities affect versions up to and including 6.6.7. Site owners using WP Travel Engine should update the plugin to the latest version as soon as possible. Both vulnerabilities can be exploited without authentication, so prompt updating is recommended to prevent unauthorized access.

Conclusion

In conclusion, the WP Travel Engine plugin has two critical vulnerabilities that can be exploited by unauthenticated attackers to gain control of a website. It is essential for site owners to update the plugin to the latest version to prevent these vulnerabilities from being exploited. By doing so, they can protect their website and sensitive data from potential attacks. The security of a website is crucial, and staying up-to-date with the latest security patches is essential to prevent cyber attacks.

- Advertisement -

Latest Articles

- Advertisement -

Continue reading

Timeline Of ChatGPT Updates & Key Events

Introduction to ChatGPT ChatGPT is a large language model developed by OpenAI that has taken the world by storm. Since its launch in 2022, it has gained a massive following, with over 700 million weekly active users as of September...

WP Engine Vs Automattic & Mullenweg Is Back In Play

Introduction to the Case WP Engine has filed a Second Amended Complaint against Automattic and Matt Mullenweg. This move comes after a September 2025 court order that dismissed several counts but allowed WP Engine to amend and fix issues in...

Why AI Search Isn’t Overhyped & What To Focus On Right Now

Introduction to AI and SEO The rise of Artificial Intelligence (AI) has sparked a mixed reaction in the SEO industry. While some believe it will have a catastrophic impact on search and SEO, others think it's business as usual. Google...

Microsoft Explains How To Optimize Content For AI Search Visibility

Introduction to AI Search Microsoft has shared guidance on structuring content to increase its likelihood of being selected for AI-generated answers across Bing-powered surfaces. Much of the advice reiterates established SEO and UX practices such as clear titles and headings,...